Practice Test Geeks home

CISA Protection of Information Assets 4

An IS auditor reviews an organization's patch management policy and finds that critical security patches are applied within 72 hours on internet-facing servers but within 30 days on internal servers.
What is the AUDITOR'S BEST assessment?

Select your answer